litigation holds: don't live in fear of spoliation (233369005)

42
Litigation Holds: Don’t Live in Fear of Spoliation Jason Pufahl @jasonpufahl CISO – University of Connecticut May 8, 2014 Information Security Office

Upload: educause

Post on 21-Jul-2016

8 views

Category:

Documents


2 download

DESCRIPTION

This presentation will offer practical guidance on establishing consistent and reliable processes needed to ensure the preservation of electronic records in response to litigation holds. The discussion will include an overview of the processes at the University of Connecticut, the rationale that went into some of the critical decision points, and tips for ensuring your process remains reasonable. OUTCOMES: Get practical guidance on the process of litigation holds and data preservation * Obtain rationale for the decisions to help adapt presentation materials to your specific needs * Understand the complexities of litigation holds and be able to apply the concept of "reasonable" to different scenarios http://www.educause.edu/events/security-professionals-conference/2014/litigation-holds-dont-live-fear-spoliation

TRANSCRIPT

Page 1: Litigation Holds: Don't Live in Fear of Spoliation (233369005)

Litigation Holds:Don’t Live in Fear of Spoliation

Jason Pufahl@jasonpufahl

CISO – University of ConnecticutMay 8, 2014

Information Security Office

Page 2: Litigation Holds: Don't Live in Fear of Spoliation (233369005)

Presentation Materials

Information Security Office

• http://s.uconn.edu/presentation

• http://s.uconn.edu/guidelines

• http://s.uconn.edu/flowcharts

Page 3: Litigation Holds: Don't Live in Fear of Spoliation (233369005)

The intentional or negligent withholding, hiding, altering, or destroying of evidence relevant to a legal proceeding

Spoliation of evidence

Information Security Office

Page 4: Litigation Holds: Don't Live in Fear of Spoliation (233369005)

Court decisions and rules place substantial obligations on public and private organizations to:

(1) preserve all electronic materials that could be relevant to pending or anticipated lawsuits

(2) retrieve and produce such materials in litigation

Information Security Office

Page 5: Litigation Holds: Don't Live in Fear of Spoliation (233369005)

Example and Catalyst

UConn’s Process Prior to 2011 : Process for hard drive collectionEmail maintained for only one year

Doe v. Norwalk Community College, 2007

• Plaintiff sued a community college for injuries suffered as a result of a sexual assault by an employee. • The court found that the college failed to preserve ESI on the computers of key witnesses. • The court held that a duty to preserve arose before the action was filed, when the college received a demand letter announcing plaintiff’s intention to sue. • The court held that the Rule 37(f) good faith exception was not available because it found that the defendant made no effort to put relevant information on “litigation hold.” • The court also said that the good faith exception was not available because the college had no routine system or consistent policy in place regarding the destruction of ESI.

Information Security Office

Page 6: Litigation Holds: Don't Live in Fear of Spoliation (233369005)

To help meet its obligations, the University created an Electronic Discovery Committee, made up of representatives from:

• Information Security Office• The Office of the Attorney General• Privacy Office• Records Management• Human Resources• General Counsel

Committee serves as a resource to assure approach is:• Consistent• Compliant with applicable laws and University policies

Electronic Discovery Committee

Information Security Office

Page 7: Litigation Holds: Don't Live in Fear of Spoliation (233369005)

• ISO Administrative Assistant (ISO Admin)

• ISO Rep• Mail and File Admin• IT Technician (IT Tech)• User Services/Accounts Desk• IT Staff

Information Security Office

Additional parties involved in the process:

Page 8: Litigation Holds: Don't Live in Fear of Spoliation (233369005)

• Cease destruction of relevant documents

• Preservation of relevant documents

• Ensure data are available for discovery

• “Reasonableness”

Guiding Principles

Information Security Office

When a case enters discovery, we can produce the expected documents consistently and within reason.

Page 9: Litigation Holds: Don't Live in Fear of Spoliation (233369005)

• Severity of litigation

• Operation efficiencies

• Individual privacy

• Risk of data loss

Factors to Consider in Records Retention

Information Security Office

Page 10: Litigation Holds: Don't Live in Fear of Spoliation (233369005)

• University workstation • employee’s home computer • mobile device • online

Information Security Office

Files must be maintained in their original form

Data to be ConsideredBusiness-related electronic information

Location Content

• email• word processing • spreadsheets• calendars• voice/text messages• wiki sites• Videos• Photographs• any other type of digital

information

Page 11: Litigation Holds: Don't Live in Fear of Spoliation (233369005)

• Litigation Hold Trackingo Legal Files

o General Counsel's Application

o Report Tracker (RT)• Manages all of UConn’s incoming requests• UConn maintains a separate file from the AG’s

office. Looking to go to Legal Files as a single clearinghouse for data.

• Secure Storage Locationo Physical – Safe/Locked spaceo Electronic - Protected

Information Security Office

Other Requirements

Page 12: Litigation Holds: Don't Live in Fear of Spoliation (233369005)

Process Components:

• Initial Litigation Hold Notice Process• Drive Imaging Process• Hard Drive Re-Image Process• Departmental IT/3rd Party Vendor Collection Process• Voluntary/Involuntary Termination Process• Litigation Hold Release Process

Information Security Office

Page 13: Litigation Holds: Don't Live in Fear of Spoliation (233369005)

INITIAL LITIGATION HOLD NOTICE

Information Security Office

Page 14: Litigation Holds: Don't Live in Fear of Spoliation (233369005)

• Every notice originates from the General Counsel’s Office

• Pre-litigation step captures email• Notification is sent to custodian• It is the custodian's responsibility to ensure all relevant

data is maintained regardless of location• Initial scope discussion between IT staff and legal staff

• administrative IT data• Collection always errs on side of “reasonable”

Highlights/Considerations

Information Security Office

Page 15: Litigation Holds: Don't Live in Fear of Spoliation (233369005)
Page 16: Litigation Holds: Don't Live in Fear of Spoliation (233369005)

DRIVE IMAGING PROCESS

Information Security Office

Page 17: Litigation Holds: Don't Live in Fear of Spoliation (233369005)

• Activation is determined by employee separation, computer repair or case severity

• Flow identifies who is imaging: internal staff or 3rd party• Complexity of case• Skill set of staff• Contracts

• Encryption keys collected and stored

• Is the original drive retained or recycled?• i.e.: removable hard drives vs. SSD

Highlights/Considerations

Information Security Office

Page 18: Litigation Holds: Don't Live in Fear of Spoliation (233369005)

Information Security Office

Page 19: Litigation Holds: Don't Live in Fear of Spoliation (233369005)

Information Security Office

Page 20: Litigation Holds: Don't Live in Fear of Spoliation (233369005)

DEPARTMENTAL IT/3RD PARTY COLLECTION PROCESS

Information Security Office

Page 21: Litigation Holds: Don't Live in Fear of Spoliation (233369005)

• Activation is determined by case complexity

• Flow identifies who is collecting: Departmental IT or 3rd party

• Collection is done based off of completed survey

Highlights/Considerations

Information Security Office

Page 22: Litigation Holds: Don't Live in Fear of Spoliation (233369005)

Information Security Office

Page 23: Litigation Holds: Don't Live in Fear of Spoliation (233369005)

VOLUNTARY/INVOLUNTARY TERMINATION PROCESS

Information Security Office

Page 24: Litigation Holds: Don't Live in Fear of Spoliation (233369005)

• Validates that at separation, relevant data are retained

Highlights/Considerations

Information Security Office

Page 25: Litigation Holds: Don't Live in Fear of Spoliation (233369005)

Information Security Office

Page 26: Litigation Holds: Don't Live in Fear of Spoliation (233369005)

LITIGATION HOLD RELEASE PROCESS

Information Security Office

Page 27: Litigation Holds: Don't Live in Fear of Spoliation (233369005)

Information Security Office

Page 28: Litigation Holds: Don't Live in Fear of Spoliation (233369005)

• ISO receives notification from the General Counsel's Office that the case is settled

• Dispersal of electronic records

Highlights/Considerations

Information Security Office

Page 29: Litigation Holds: Don't Live in Fear of Spoliation (233369005)

Critical Points

• Relationship with General Counsel

• Process must satisfy both General Counsel and IT staff

• Define reasonable processes

• Adhere to those processes

Information Security Office

Page 30: Litigation Holds: Don't Live in Fear of Spoliation (233369005)

Attachments

Information Security Office

Page 31: Litigation Holds: Don't Live in Fear of Spoliation (233369005)

Information Security Office

Page 32: Litigation Holds: Don't Live in Fear of Spoliation (233369005)

Information Security Office

Page 33: Litigation Holds: Don't Live in Fear of Spoliation (233369005)

Information Security Office

Page 34: Litigation Holds: Don't Live in Fear of Spoliation (233369005)

Information Security Office

Page 35: Litigation Holds: Don't Live in Fear of Spoliation (233369005)

Information Security Office

Page 36: Litigation Holds: Don't Live in Fear of Spoliation (233369005)

Information Security Office

Page 37: Litigation Holds: Don't Live in Fear of Spoliation (233369005)

Information Security Office

Page 38: Litigation Holds: Don't Live in Fear of Spoliation (233369005)

Information Security Office

Page 39: Litigation Holds: Don't Live in Fear of Spoliation (233369005)

Thank You

JASON PUFAHLCISO

[email protected]

Information Security Office

Page 40: Litigation Holds: Don't Live in Fear of Spoliation (233369005)

Our sincerest thanks to all attendees joining us in person and online.On behalf of the 2014 Security Professionals Conference Program Committee

Page 41: Litigation Holds: Don't Live in Fear of Spoliation (233369005)

A few important reminders: Complete the overall conference evaluation.

You’ll receive an e-mail reminder soon.

Lunch for REN-ISAC Member Meeting & postconference seminar attendees will be held in the Arch View Ballroom, 12-1 pm.

We hope you’ve been inspired by your peers, made new connections, and identified some tangible takeaways.

Page 42: Litigation Holds: Don't Live in Fear of Spoliation (233369005)

May the force be with you!